AI Academy · Book
Executives & Directors · Module 06 · Chapter 006

Intellectual Property and Copyright

AI-generated does not mean we own it, and sometimes it means nobody can. Rights in AI-assisted work depend on what went in, the terms of the tool, the law of each market and what people actually contributed. Leaders who keep those questions separate, and keep a record for the assets that matter, can move fast without building on sand.

≈ 15 min read

After this chapter you can

  • Distinguish copyright, patents, trademarks and trade secrets as different AI risks.
  • Explain why input rights and output rights are separate questions at every stage.
  • Describe the US position on purely AI-generated material and why the UK and other markets may differ.
  • Recognize unapproved AI tools as a trade-secret leakage channel and indemnities as conditional.
  • Scale review and provenance records to the value and exposure of the asset.

In September 2022 the US Copyright Office registered a comic book called Zarya of the Dawn. Its author, Kristina Kashtanova, had written the story and laid out the pages; the pictures came from an AI image generator. She held a certificate of registration. Five months later the Office cancelled it and issued a narrower one. The text was hers. So was the selection and arrangement of words and pictures on the page. The images themselves, the Office said, were not the product of human authorship and were protected by no one1.

That is the contradiction at the center of this chapter. A comic can be protected while every picture in it is not. A company can hold an asset, use it, sell it and still be unable to stop a competitor from copying it. Many executives assume that whoever makes or pays for a piece of work owns it. With AI, that assumption fails in specific and predictable ways.

The contract says yours; the law may say nobody’s

Read the terms of many major AI services and you will find reassuring language about outputs. One widely used provider’s terms say the customer owns the output and that the provider assigns to the customer all of its rights in the output, “if any”2. Those two words carry the weight. A provider can only hand over what exists. If the law grants no copyright in a purely generated image, the assignment transfers very little.

The provider contract assigns output rights to the customer, but US law grants no copyright in purely AI-generated material, so there may be nothing to assign.THE PROVIDER CONTRACTThe output is yours; weassign our rights, if any.Feels settledUS COPYRIGHT LAWPurely AI-generated materialis not copyrightable.Nobody may own itvs
Figure 6.6.1 Both documents can be true at once. A contract cannot hand over a right the law never created.

So the core idea is simple to state. AI-generated does not automatically mean we own it, and in some cases it means nobody can. Nor does it mean original, unrestricted or safe to commercialize. Each of those is a separate question, and each needs an answer before an AI-assisted asset leaves the building. AI changes the speed and scale of creation; it does not make intellectual-property questions go away. It multiplies them, because there is far more content, made far faster, with far less visibility into where it came from. The US government’s risk profile for generative AI lists intellectual property among its twelve core risks for exactly that reason3.

Four rights, four different risks

Intellectual property is not one right but a family, and AI touches each member differently. When someone in a meeting says “the IP question”, the first useful response is to ask which one.

Intellectual property is four rights - copyright, patents, trademarks and trade secrets - and AI creates a different risk for each.CopyrightText, images, code - canwe own and use it?PatentsWho invented it - can weshow it?TrademarksDoes it imitatesomeone's brand?Trade secretsDid something valuableleave our control?
Figure 6.6.2 Four rights, four risks. A single AI-assisted asset can raise more than one.

Copyright protects original expression: text, images, music, video and software code. AI meets copyright three times, as the material it learned from, as the material you feed it and as the material it produces. Patents protect inventions, and AI raises the question of who invented something. In December 2023 the UK Supreme Court held that an AI system cannot be named as an inventor on a patent application; an inventor must be a person4. Where AI contributes to research, the evidence of what your people conceived matters. Trademarks protect names, logos and slogans. A generated campaign image can drift close to a competitor’s mark, or reproduce one outright. Trade secrets protect valuable information that is not generally known, but only while the owner takes reasonable measures to keep it secret. Source code, pricing models, customer lists and process know-how all qualify, and all of them can be pasted into a chat window in seconds.

Risk enters at four stages, not at publication

Many organizations think about IP only at the moment of release, when legal reviews the campaign or the product. By then, much of the risk is already inside the asset. It is more useful to follow an asset through its life.

Risk enters at input, AI tool, output and release; clearing the rights at one stage does not clear them at the next.InputDo we have theright to use itthis way?AI toolWhat do theseterms say?OutputDoes it match orcontain someoneelse's work?ReleaseProduct,campaign ordeliverableInput rights are not output rights
Figure 6.6.3 Clearing one stage does not clear the next. The cost of a mistake rises at each step.

At input, someone gives the system an article, a photograph, a competitor’s brochure or a block of code. Publicly available does not mean free for any use. At the tool, the provider’s terms decide what happens to that input, what the provider may do with it and what the customer receives; terms differ by product, plan and region, so the only terms that matter are those of the service your people actually used. At output, the question is whether the result reproduces or closely resembles existing work. New to us is not the same as legally unrestricted. At release, the asset goes into a product, a campaign or a customer deliverable, and a mistake becomes expensive.

The most prominent legal fights so far concern a fifth stage that sits with the providers: training. A US court gave final approval in July 2026 to a 1.5 billion dollar settlement over books used to train a model5, and in November 2025 the UK High Court largely ruled for a model maker against a photo agency6. For a company that buys AI rather than builds it, those cases matter mainly through vendor due diligence. Your direct exposure is what your people put in and what they ship.

What the law protects, and what it does not

The ownership question needs care, and it varies by country. In January 2025 the US Copyright Office published its report on the copyrightability of AI output. Its conclusion is that material generated purely by AI is not copyrightable. Prompts alone, however detailed, do not give a person enough control over the output to make them its author. What can be protected is the human part: creative work that is visible in the output, the creative selection and arrangement of generated material, and creative modifications made to it7. The courts agree. In Thaler v. Perlmutter, a federal appeals court upheld the refusal to register an image whose only listed author was an AI system, and on 2 March 2026 the Supreme Court declined to hear the case8.

A purely AI-generated asset is not copyrightable in the US; the UK has a computer-generated works provision under review; human selection, arrangement and modification can be protected.PurelyAI-generated assetUS: not copyrightableCompetitors may copy itUK: a computer-generated works provision, under reviewAsk counsel per marketHUMAN CONTRIBUTION COUNTSSelectionArrangementModification
Figure 6.6.4 The same asset can be treated differently in different markets. Human contribution is what travels.

Other countries differ. Since 1988 UK law has contained a provision, section 9(3) of the Copyright, Designs and Patents Act, under which the author of a computer-generated work is the person who made “the arrangements necessary” for it. How far that provision reaches modern generative AI has not been settled by the courts. In March 2026 the UK government said it would keep that provision under review and proposed to remove it unless evidence shows ongoing value, while keeping protection for works made with AI assistance9. So the US answer does not travel automatically, and the UK answer may change. What travels everywhere is documented human contribution.

The practical consequence is commercial, not academic. If a logo, a product design or a block of code is purely generated, a competitor may be free to copy it, and you may have little to enforce. That is a weak foundation for a brand asset or a differentiating product. It is a fine foundation for an internal draft.

Trade secrets leak on the way in

The second IP risk has nothing to do with who owns the output. It is about what leaves on the way in. A developer on deadline pastes proprietary code into a free chatbot to ask why it fails, or an analyst pastes a pricing model to tidy it up. Nobody intends a leak; each person is asking for help with their work. A widely reported case, at Samsung in 2023, is told in What Is AI Governance? in Module 0710.

Privacy and Confidential Data treated this pattern as a data-protection problem. For intellectual property it is sharper, because a trade secret exists only while its owner takes reasonable measures to keep it secret. Letting valuable code or formulas flow into tools the company does not control is precisely the kind of fact an opponent will use to argue that those measures were not reasonable.

High-value information in an unapproved tool is the leakage danger; approved tools with controls that rise with value protect it better than a ban.HighLowInformationvalueUnapprovedTool control · ApprovedLeakage riskSecrets leave our controlStronger controlsRestricted inputs and accessSteer and trainMove people to approved toolsRoutine useNormal policy
Figure 6.6.5 The danger is high-value information in an uncontrolled tool. The answer is a better tool, not a ban.

Many organizations’ first move is a ban, and a ban is understandable as an emergency brake. As a standing policy it tends to push use into personal accounts, which is the top-left corner of the grid. The more durable answer is approved enterprise tools whose terms you have read, clear rules on which classes of information may go in, and controls that tighten as the value of the information rises.

Terms, indemnities and generated code

Two contractual instruments shape your position, and both reward reading the small print. The first is the provider’s terms on inputs and outputs, discussed above. The second is the indemnity, a promise by the provider to defend you if someone sues over the output. These are valuable, and they come with conditions. One large provider’s copyright commitment, for example, covers paying commercial customers only if they used the guardrails and content filters built into the product, and does not extend to free or consumer versions11. An indemnity can pay a settlement. It cannot restore a leaked trade secret, and it does not make an output yours.

Software is where the abstract becomes concrete, because generated code can carry someone else’s license with it. Open source is not free of obligations; some licenses require attribution, and some require that a product built on the code release its own source. Black Duck, which audits codebases during acquisitions, found open source in 98 percent of the 947 codebases it examined for its 2026 report and license conflicts in 68 percent, up from 56 percent a year earlier. It points to AI coding assistants as a driver. Those figures count audited codebases. A separate Black Duck survey counts organizations: 76 percent check AI-generated code for security risks, but only 54 percent check it for IP and license risks12.

License conflicts appeared in 68 percent of audited codebases, and only 54 percent of organizations check AI-generated code for IP and license risk, against 76 percent for security.68%Codebases withlicense conflictsUp from 56% a year earlier76%Check AI codefor securitySurvey of organizations54%Check AI code for IPand licensesSame survey; the gapleaders ownSource: Black Duck OSSRA · 2026
Figure 6.6.6 The first tile counts audited codebases; the other two count surveyed organizations. Three in four test AI code for security, about half for whose code it is.

Review depth follows the stakes

None of this argues for a lawyer behind every prompt. Much AI-assisted work is internal, low-value and short-lived. The right control is proportionate: review deepens as the asset’s value and exposure rise.

Review depth rises from internal drafts to commercial assets, which need a provenance record and IP counsel.CommercialassetProvenance record and IP counselForcustomersBrand, claims, similarityInternalrelianceCheck accuracy and sourcesInternal draftApproved tool onlySTAKESRISE
Figure 6.6.7 Not every email needs a file. Every product, invention and core software asset does.

At the top tier sits the provenance record: which tool and version produced the material, what went in and where it came from, what your people selected, arranged and changed, what review happened and who decided to release it. The record is short. Its value shows up later, when a customer, an acquirer or a court asks where an asset came from. An AI-assisted asset without one is like a painting bought with no provenance: it hangs on the wall and may be valuable, but you cannot prove the seller had the right to sell it, or stop others from copying it. Zarya of the Dawn kept its narrower registration precisely because its author could show what she wrote and how she arranged the pages. How such records become a governance process is the subject of Module 07.

Story: the marketing image nobody could vouch for

For Wizards of the Coast, art is much of the product: the illustrations on its cards and in its books are what players collect. In August 2023 players spotted signs of AI in illustrations for a forthcoming Dungeons & Dragons sourcebook. The company said it had not known that an artist had used AI, and that it was “revising our process and updating our artist guidelines to make clear that artists must refrain from using AI art generation as part of their art creation process”13. It later replaced the affected art14. In December 2023 it set the same line for Magic: “We require artists, writers, and creatives contributing to the Magic TCG to refrain from using AI generative tools to create final Magic products”14.

On 4 January 2024 the company posted a promotional image for Magic on social media15. Players pointed to signs of generation, such as wires that led nowhere and bulbs with impossible filaments. The company replied, in a post it later deleted, “This art was created by humans and not AI.” On 7 January it reversed itself: “Well, we made a mistake earlier when we said that a marketing image we posted was not created using AI.” AI components now appearing in industry-standard tools such as Photoshop, it explained, had “crept into our marketing creative, even if a human did the work to create the overall image”16. Its explanation pointed to a third-party vendor that had supplied the work15.

One promotional image with AI traces revealed rules that did not reach vendors, no record of the tools used, AI inside standard software, a denial followed by a retraction, and generated parts that are not protectable in the US.WHAT PLAYERS SAWOne promotional image with AI tracesWHAT IT REVEALEDVendors outside the rulesNo record of the tools usedAI inside standard softwareA public denial - then a retractionGenerated parts unprotectable
Figure 6.6.8 The visible problem was one image. The real problem was a process that could not say how its assets were made.

The company had a rule; what it lacked was a way to check it. The rule bound the artists who made products, not the vendors who made marketing. Nothing on file recorded which tools had produced the image, so the first public answer had to come from belief rather than evidence, and it did not survive three days. And the tools themselves had moved: once generative features sit inside mainstream editing software, “did we buy an AI tool?” no longer answers “is there AI in this asset?”. For a business built on art it owns, there is a rights question underneath as well, since in the US purely generated elements are not protectable7.

The fix the company announced was a process, not a single takedown. It said it needed “to update the way we work with vendors on creative beyond our products—like marketing images we use on social media,” and it called for more transparency and better disclosure as generative AI becomes standard in tools such as Photoshop17. That is the provenance record of this chapter, written into supplier relationships. The lesson is not about one publisher: any organization that buys creative work, code or content now needs suppliers to say what made it.

What this means for leaders

Four habits follow. Separate the questions: whether we may use the input, what the terms say, whether the output is clean and whether we can own it are four answers, not one. Protect what goes in, because a trade secret lost to an uncontrolled tool cannot be recalled and no indemnity restores it. Make the human contribution visible for anything you intend to protect, since that is what US law protects. And scale review to the stakes, so that drafts move fast and commercial assets carry a record.

Check yourself

  1. If our AI tool created it and the provider’s terms assign the output to us, the company owns the copyright.
  2. In the US, a detailed enough prompt makes the person who wrote it the author of the output.
  3. A work can be registered for copyright even though some images in it are AI-generated.
  4. A provider indemnity means we carry no IP risk.
  5. Pasting proprietary code into an unapproved AI tool can weaken trade-secret protection.
  6. Generated code is original, so it cannot carry open-source license obligations.

Reflection: trace one asset

What comes next

Every answer in this chapter rests on a provider: the organization whose model, terms and indemnities you depend on. The next chapter, Model and Third-Party Risk, asks what happens when that provider is itself the risk.

Laws referenced

US copyright and AI-generated work · US

US Copyright Office, Copyright and Artificial Intelligence Part 2: Copyrightability (Jan 2025); Thaler v. Perlmutter (D.C. Cir. 2025; cert. denied 2 Mar 2026)

Material generated purely by AI is not copyrightable; human-authored contributions (selection, arrangement, modification) can be. Nobody may own a purely AI-generated asset, so competitors may be free to copy it. Other countries differ (e.g. the UK's computer-generated works provision).

Last verified 2026-10-06

References

  1. U.S. Copyright Office. Letter re: Zarya of the Dawn (Registration # VAu001480196). U.S. Copyright Office. 2023.
  2. OpenAI. Terms of Use. OpenAI. 2024.
  3. National Institute of Standards and Technology. Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile, NIST AI 600-1. NIST. 2024.
  4. The Supreme Court of the United Kingdom. Thaler v Comptroller-General of Patents, Designs and Trade Marks [2023] UKSC 49. The Supreme Court of the United Kingdom. 2023.
  5. The Authors Guild. Court Grants Final Approval of 1.5 Billion Dollar Anthropic Copyright Settlement. The Authors Guild. 2026.
  6. Cleary Gottlieb. UK High Court Issues Landmark Ruling in Getty Images v. Stability AI, with Narrow Trademark Infringement Win for Getty; Claim of Secondary Copyright Infringement Fails. Cleary Gottlieb Steen & Hamilton. 2025.
  7. U.S. Copyright Office. Copyright and Artificial Intelligence, Part 2: Copyrightability. U.S. Copyright Office. 2025.
  8. Finnegan. Supreme Court Declines to Hear Thaler v. Perlmutter, Leaving Human Authorship Requirement Intact. Finnegan, Henderson, Farabow, Garrett & Dunner. 2026.
  9. UK Government (Department for Science, Innovation and Technology; Intellectual Property Office). Report on Copyright and Artificial Intelligence. GOV.UK. 2026.
  10. Mark Gurman. Samsung Bans Staff's AI Use After Spotting ChatGPT Data Leak. Bloomberg. 2023.
  11. Microsoft. Microsoft announces new Copilot Copyright Commitment for customers. Microsoft On the Issues. 2023.
  12. Black Duck. Black Duck Research Shows Open Source Vulnerabilities Have Doubled as AI Accelerates Code Creation (2026 OSSRA report). Black Duck. 2026.
  13. Matt Bassil. Wizards promises new guidelines to keep AI art out of DnD. Wargamer. 2023.
  14. James Whitbrook. Magic: The Gathering Formally Bans the Use of Generative AI in 'Final' Products. Gizmodo. 2023.
  15. Tara McCauley. Magic: The Gathering Admits AI Used in Marketing Image. The Escapist. 2024.
  16. Futurism. Wizards of the Coast Denies "Magic: The Gathering" Art Was AI-Generated, Then Admits It Was. Futurism. 2024.
  17. Wizards of the Coast. An Update on Generative AI Tools and Magic. Wizards of the Coast (magic.wizards.com). 2024.

Further reading

Sources last verified 2026-10-08.